Purchase Terms and Conditions
Legal Notices for Arrow International, Inc.
These Purchase Terms and Conditions (“Terms”) govern the purchase of products, equipment, deliverables or other goods (“Products”), services (“Services”), and software (including any software license, subscription, hosted or cloud-based software, software-as-a-service, updates, upgrades, patches, and related documentation) (collectively, “Software”), as applicable, by and between Arrow International, Inc. or its affiliate identified in the purchase order incorporating these Terms (“Customer”) and the party to whom the purchase order was issued (“Supplier”) in the absence of a signed agreement between Customer and Supplier for the purchase of the Products, Services, or Software. In the event a signed agreement is executed between Customer and Supplier, the signed agreement shall control to the extent of any conflict with these Terms. By accepting the purchase order or delivering Products or Software or performing the Services, Supplier agrees to be bound by these Terms.
1. Acceptance; Entire Agreement. In the absence of a signed agreement between Customer and Supplier, these Terms, together with the applicable purchase order and Appendix A (IT Vendor Security Addendum), constitute the entire agreement between the parties regarding the subject matter herein. Any additional or conflicting terms provided by Supplier in any acknowledgment, invoice, or other communication are expressly rejected and shall be of no force or effect.
2. Warranties. Supplier represents and warrants that all Products: (a) are new and free from defects in materials, workmanship, and design; (b) conform to the specifications, drawings, and descriptions provided by Customer; (c) are fit for their intended purpose; and (d) Supplier has good and marketable title to all Products provided, and all Products are free from any liens, claims, or encumbrances. Supplier represents and warrants that all Services shall be performed and completed, and all other deliverables hereunder shall be prepared and provided, by Supplier in accordance with the specifications and instructions provided by Customer, by competent, qualified personnel, suitably trained and experienced in the areas of such services, in a timely, professional, workperson-like manner, in compliance with all applicable laws, rules, regulations, and ordinances, and in accordance with all recognized professional practices and standards in the industry. Supplier represents and warrants that all Software (and any deliverables comprising or including Software): (a) will conform in all material respects to the specifications, documentation, and descriptions provided by Supplier and/or agreed in the purchase order; (b) will be free from material defects and will perform in accordance with generally accepted industry standards; (c) will not contain any viruses, worms, Trojan horses, time bombs, back doors, or other malicious code or disabling devices; and (d) does not and will not infringe or misappropriate any patent, copyright, trade secret, trademark, or other intellectual property right. These warranties shall survive delivery and acceptance for a period of at least twelve (12) months, unless a longer period is provided by law or warranty.
3. Intellectual Property
b. Exclusivity. Supplier shall not manufacture, sell, or distribute to any third party any product that is the same as, or substantially similar to, any Product manufactured for Customer that incorporates Customer IP, work product created for Customer, or tooling paid for by Customer, or that is derived from any design, specification, or configuration provided by or developed for Customer. This restriction applies during the term of any purchase order and for two (2) years following the last purchase order for the applicable Product. Supplier acknowledges that this exclusivity is a material term of the purchase relationship and that breach would cause irreparable harm to Customer.
c. Supplier Pre-Existing IP; Cooperation. To the extent any Product incorporates Supplier’s pre-existing intellectual property not created for Customer, Supplier grants Customer a perpetual, irrevocable, worldwide, royalty-free license to use, modify, reproduce, distribute, and sublicense such pre-existing IP as incorporated in the Products, including for Customer’s resale and distribution. Supplier shall cooperate with Customer in obtaining patents, design registrations, and other IP protections for work product, at Customer’s expense, and shall promptly disclose to Customer any inventions or improvements made in connection therewith. Supplier shall execute any documents reasonably requested by Customer to perfect, register, or enforce Customer’s rights.
4. IT Security Addendum. “Customer Data” means any and all data, content, records, files, materials, and information (including personal data) that is (a) provided or made available by or on behalf of Customer or any Customer affiliate to Supplier, or to any Software, Products, or Services, (b) accessed, collected, processed, stored, hosted, generated, derived, or created by Supplier or any of its subcontractors in connection with the Software, Products, or Services, or (c) received by Supplier or any of its subcontractors from or through Customer Systems, in each case in any form or medium and whether or not such data is then in Supplier’s possession or control. Customer Data includes any results, output, analytics, inferences, learnings, or other information to the extent derived from or based on Customer Data. “Customer Systems” means Customer’s and its affiliates’ information technology environment, including networks, systems, servers, hardware, software, applications, websites, databases, endpoints, cloud services, accounts, credentials, and other infrastructure and systems that Customer (or its users) owns, licenses, operates, or uses, or to which Supplier is provided access, in connection with the Software, Products, or Services. To the extent applicable to the Software, Products, or Services (including any access to, processing of, or transmission of Customer Data or Customer Systems), Supplier shall comply with the IT Vendor Security Addendum attached hereto as Appendix A, which is incorporated herein by reference. In the event of a conflict between these Terms and Appendix A with respect to security, privacy, or data protection requirements, Appendix A shall control.
5. Delivery; Risk of Loss; Inspection; Payment Terms. Time is of the essence. Delivery of the Products and Software and performance of the Services shall be made in accordance with the schedule set forth in the purchase order. Title and risk of loss of the Products shall pass to Customer only upon receipt and acceptance at Customer’s designated delivery location. Customer shall have the right to inspect the Products upon delivery and the Services following performance thereof, and may reject any Products that are non-conforming. Rejected Products, at Customer’s option, may be returned to Supplier at Supplier’s expense for repair, replacement, or refund. Customer, at its option, may require that non-conforming Services be re-performed or refunded. If Customer notifies Supplier of nonconforming Software within such period (or within the warranty period), Supplier will promptly correct the nonconformity at its expense; if Supplier does not do so within ten (10) business days, Customer may terminate the affected Software and receive a refund of fees paid for it. All claims for monies due or to become due from Customer shall be subject to deduction by Customer for any setoff or counterclaim arising out of this or any other of Customer’s transactions with Supplier. Except if disputed by Customer in good faith, Customer will pay Supplier’s invoice within 45 days of receipt. Customer may inspect and test Software for thirty (30) days after delivery/provisioning (or such other period stated in the purchase order).
6. Confidentiality. The parties shall maintain confidential information in accordance with the terms and conditions of any confidentiality agreement entered into between Customer and Supplier; provided, however, that if the parties have not entered into a separate confidentiality agreement, Supplier acknowledges and agrees that Customer’s property, as well as the terms of the purchase order and the existence and content of the relationship between the Supplier and Customer, shall be treated as confidential and shall not be used or disclosed by Supplier except as required in the course of performance hereunder or under other purchase orders of Customer. Supplier shall protect the confidentiality of all such information with the same degree of care it uses to protect its own confidential information, but in no event less than a reasonable standard of care. Unless otherwise agreed to in writing by Customer, information and material furnished or disclosed by Supplier to Customer shall not be considered to be confidential or proprietary, and shall be acquired by Customer free of restrictions of any kind.
7. Limitation of Liability. Neither party shall be liable to the other for indirect, incidental, consequential, or punitive damages, including loss of profits or business, arising out of these Terms. Notwithstanding the foregoing, this limitation shall not apply to: (a) a party’s gross negligence or willful misconduct; (b) Supplier’s indemnification obligations; (c) damages arising from a breach of confidentiality; (d) Supplier’s violation of applicable law; (e) Supplier’s breach of Section 3 (Intellectual Property); or (f) Supplier’s breach of Appendix A (IT Vendor Security Addendum).
8. Indemnification. Supplier shall defend, indemnify, and hold harmless Customer and its affiliates, officers, directors, and employees from and against any and all claims, liabilities, damages, losses, and expenses, including attorneys’ fees, arising out of or in connection with: (a) any breach of these Terms; (b) any claim that the Products, Services, or Software infringe any patent, copyright, trademark, or other intellectual property right; (c) any bodily injury, death, or property damage caused by the Services, Products, Software, or Supplier’s acts or omissions; or (d) any violation of applicable law.
9. Insurance. Supplier shall maintain, at its own expense, insurance policies sufficient to cover its obligations under these Terms, including but not limited to: (a) Commercial General Liability ($1,000,000 per occurrence), (b) Product Liability Insurance, (c) Workers’ Compensation as required by applicable law, and (d) such other coverage as a reasonable purchaser would expect given the nature of the Products or Services, as applicable. Upon request, Supplier shall provide certificates of insurance evidencing such coverage.
10. Force Majeure. Neither party shall be liable for delays or failure to perform due to causes beyond its reasonable control, including natural disasters, acts of God, war, terrorism, epidemics, labor strikes, or government actions. The affected party must promptly notify the other party and make reasonable efforts to resume performance.
11. Compliance with Laws. Supplier shall comply with all applicable laws, rules, and regulations, including but not limited to: (a) the U.S. Foreign Corrupt Practices Act (“FCPA”), (b) applicable export control laws, and (c) all applicable labor, health, safety, and environmental laws. Supplier shall not offer or provide any illegal or improper payments, gifts, or anything of value to any government official or third party.
12. Independent Contractors. The parties are independent contractors. Nothing in these Terms creates a partnership, joint venture, agency, or employment relationship between the parties.
13. Audit Rights. Customer shall have the right, upon reasonable notice and during normal business hours, to audit Supplier’s books, records, and facilities as necessary to verify compliance with these Terms, including but not limited to pricing, delivery, legal compliance, and Supplier’s obligations under Sections 3 (Intellectual Property), 6 (Confidentiality), and Appendix A (IT Vendor Security Addendum).
14. Publicity. Supplier shall not use Customer’s name, logo, or trademarks, or make any public announcements regarding the existence or nature of the relationship, without Customer’s prior written consent in each instance.
15. Governing Law; Jurisdiction. These Terms shall be governed by and construed under the laws of the State of Ohio, without regard to its conflict of law principles. Any disputes shall be resolved in the state or federal courts located in Ohio, and Supplier consents to the exclusive jurisdiction of such courts.
16. Assignment and Subcontracting. Supplier may not assign or subcontract its obligations without Customer’s prior written consent. Any unauthorized assignment is void.
17. Waiver; Severability. No waiver by either party of any provision shall be deemed a waiver of any other provision or a continuing waiver. If any provision is held invalid or unenforceable, the remaining provisions shall remain in full force and effect.
18. Remedies. Supplier acknowledges that any breach of Section 3 (Intellectual Property) or Section 6 (Confidentiality) would cause irreparable harm to Customer for which monetary damages would be inadequate. Customer shall be entitled to seek injunctive and other equitable relief in addition to all other remedies available at law or in equity, without the requirement of posting a bond.
19. Survival. Sections 2, 3, 4, 6, 7, 8, 13, 15, 18, and any other provisions that by their nature should survive termination shall survive the completion or termination of the purchase order.
APPENDIX A
IT VENDOR SECURITY ADDENDUM
This Security Addendum (“Addendum”) is attached to and incorporated into the Purchase Terms and Conditions (“Terms”) by and between Arrow International, Inc. or its affiliate identified on the purchase order (“Customer”) and the party to whom the purchase order was issued (“Supplier”). This Addendum and the Terms apply in the absence of a signed agreement between Customer and Supplier. In the event a signed agreement is executed, the signed agreement shall control to the extent of any conflict with this Addendum or the Terms. Capitalized terms used but not defined in this Addendum have the meanings assigned to them in the Terms. This Addendum applies only to the extent the Products, Services, or Software involve (a) access to, processing of, storage of, or transmission of Customer Data, or (b) access to or interaction with Customer Systems. In the event of any conflict between this Addendum and the Terms with respect to security, privacy, or data protection requirements, this Addendum shall control.
1. INCIDENT NOTIFICATION 1.1 In the event of a Security Incident or Data Breach (each, a “Critical Incident”) involving Customer Data or Customer Systems, Supplier shall notify Customer without undue delay and in any event within seventy-two (72) hours of becoming aware of such Critical Incident. For the purposes of this Addendum:
(b) “Data Breach” means a confirmed incident resulting in the unauthorized access, use, disclosure, modification, or destruction of Customer Data, including both accidental exposure and deliberate attacks that lead to the compromise of personal, confidential, or sensitive information.
2. AUDIT RIGHTS
2.1 Supplier shall provide Customer with an annual SOC 2, Type 2 report, conducted by an independent third-party auditor.
2.2 Customer reserves the right to conduct additional audits or assessments of Supplier’s security controls with reasonable notice.
3. SERVICE LEVEL AGREEMENTS Supplier agrees to meet or exceed the following service levels:
3.1 System Availability: Minimum 99.9% uptime for all critical systems, measured monthly, excluding scheduled maintenance.
3.2 Incident Response Times: (a) Critical Incidents: initial response within 30 minutes, updates every 2 hours; (b) High Priority: initial response within 2 hours, updates every 4 hours; (c) Medium Priority: initial response within 4 hours, daily updates; (d) Low Priority: initial response within 1 business day, weekly updates.
3.3 Incident Resolution Times: (a) Critical: within 4 hours; (b) High Priority: within 8 hours; (c) Medium Priority: within 3 business days; (d) Low Priority: within 10 business days.
3.4 Security Patch Implementation: (a) Critical patches: within 24 hours; (b) High priority: within 72 hours; (c) Other patches: within 10 business days.
3.5 Backup and Recovery: (a) Daily incremental and weekly full backups; (b) 99.9% backup success rate; (c) Critical data restored within 4 hours, all other within 24 hours.
3.6 Support Availability: (a) 24/7 for Critical and High Priority Incidents; (b) Standard business hours (9 AM–5 PM, M–F) for Medium and Low Priority.
3.7 Security Monitoring: Continuous 24/7 monitoring and alerting for all critical systems.
3.8 Reporting: Monthly performance and compliance reports within 5 business days of month-end.
3.9 SLA Failures: (a) Root cause analysis and corrective action plan within 5 business days; (b) Service credits: 5% of monthly fee for Critical/High failures, 2% for Medium, 1% for Low; (c) Total credits capped at 25% of monthly fee.
3.10 Continuous Improvement: Annual SLA review in collaboration with Customer.
4. SUBCONTRACTOR SECURITY
4.1 Supplier shall ensure that any subcontractors engaged in the processing of Customer Data adhere to the same security standards as this Addendum. “Subcontractor” means any third party engaged by Supplier to perform services or process Customer Data, including cloud providers, data processing vendors, and managed service providers.
4.2 Supplier shall maintain a current list of subcontractors and provide it to Customer upon request.
5. DATA RETENTION AND DESTRUCTION
5.1 Supplier shall retain Customer Data only for the duration necessary to fulfill the purchase order, unless longer retention is required by law.
5.2 Upon completion or termination (or at Customer’s request), Supplier shall securely return or destroy all Customer Data (including data held by Subcontractors), and upon request provide written certification of destruction.
5.3 Supplier may retain Customer Data beyond termination solely as required by law or for bona fide archival purposes, provided: (a) Supplier informs Customer in writing of the data types and purpose; (b) data is stored securely with strictly limited access; and (c) data is not used for any other purpose without Customer’s written consent.
5.4 All security obligations in this Addendum remain in effect for as long as Supplier retains any Customer Data.
6. CONFIDENTIALITY
6.1 Supplier shall treat all Customer Data as confidential and shall not disclose it to any third party without Customer’s prior written consent.
6.2 Supplier shall ensure that its employees and subcontractors are bound by confidentiality obligations no less restrictive than this Addendum.
7. DATA BREACH LIABILITY
7.1 Supplier shall be liable for damages resulting from a Security Incident or Data Breach caused by its negligence or failure to comply with this Addendum.
7.2 Supplier shall maintain appropriate insurance coverage for liabilities arising from Security Incidents or Data Breaches, consistent with the insurance requirements in the Terms.
7.3 The limitation of liability applicable to Security Incidents or Data Breaches shall be as set forth in the Terms.
7.4 For clarity, uncapped damages may include: (a) investigation and forensic costs; (b) notification costs; (c) legal fees; (d) regulatory fines and penalties; (e) compensation to affected individuals; (f) reputational damage costs; (g) business interruption costs; and (h) any other direct or indirect losses from the breach.
8. ENDPOINT SECURITY CRITERIA Supplier shall implement and maintain the following endpoint security measures:
8.1 Advanced Malware Protection: Up-to-date antivirus and anti-malware on all endpoints.
8.2 Endpoint Detection and Response (EDR): Continuous monitoring, real-time alerts, and rapid incident response.
8.3 Full-Disk Encryption: All endpoints must use full-disk encryption.
8.4 Patch Management: Critical vulnerability patches within 30 days of release.
8.5 Access Control and Authentication: Multi-factor authentication and least-privilege access for all endpoint users.